{"id":21254,"date":"2026-09-24T11:42:05","date_gmt":"2026-09-24T11:42:05","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=21254"},"modified":"2026-09-24T11:42:05","modified_gmt":"2026-09-24T11:42:05","slug":"cisco-ccnp-data-center-300-620-practice-test-questions-and-exam-dumps-part20-q381-400","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/cisco-ccnp-data-center-300-620-practice-test-questions-and-exam-dumps-part20-q381-400\/","title":{"rendered":"Cisco CCNP Data Center 300-620 Practice Test Questions and Exam Dumps Part20 Q381-400"},"content":{"rendered":"<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/300-620-exam-dumps\"><b>Cisco CCNP Data Center 300-620 Exam Dumps<\/b><\/a><b> and Practice Test Dumps.<\/b><\/h2>\n<p>&nbsp;<\/p>\n<h3><b>Question 381<\/b><\/h3>\n<p><b>Which ACI component provides the centralized interface for configuring tenants, EPGs, contracts, and fabric policies?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Spine switch<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">APIC<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Leaf switch<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">External router<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">APIC provides the centralized management and policy interface for Cisco ACI. Administrators use APIC to configure tenants, VRFs, bridge domains, EPGs, contracts, access policies, external connectivity, and monitoring settings. Leaf switches enforce policy and provide endpoint connectivity, while spine switches primarily provide fabric transit. External routers provide connectivity to networks outside the ACI fabric. APIC also maintains the policy database and coordinates configuration across the fabric. When troubleshooting configuration issues, administrators can use APIC to inspect faults, health scores, policy deployment, endpoint information, and fabric status. This centralized approach supports consistent policy management throughout the ACI environment.<\/span><\/p>\n<h3><b>Question 382<\/b><\/h3>\n<p><b>Which ACI object defines the Layer 3 routing context for a collection of bridge domains?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Filter<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Contract<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">VRF<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">VLAN pool<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A VRF defines the Layer 3 routing context for bridge domains in ACI. Multiple bridge domains can share the same VRF and therefore participate in the same logical routing table. Separate VRFs provide routing isolation between different environments or tenants. Filters define traffic characteristics, contracts establish communication policies, and VLAN pools provide encapsulation resources. When troubleshooting routing between bridge domains, administrators should verify that the bridge domains are associated with the intended VRF and that their subnets and routing policies are configured correctly. Proper VRF design prevents unintended route sharing and supports logical segmentation within the ACI fabric.<\/span><\/p>\n<h3><b>Question 383<\/b><\/h3>\n<p><b>Which ACI feature is used to explicitly attach an EPG to a physical leaf interface with a specified encapsulation VLAN?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Static path binding<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Preferred group<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Route control<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">BFD<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Static path binding explicitly associates an EPG with a physical leaf interface or path and specifies the VLAN encapsulation used for the connection. It is commonly used for bare-metal servers and other physical endpoints. Preferred groups influence communication between selected EPGs, route-control policies influence external routing, and BFD provides rapid failure detection. When configuring static path binding, administrators should verify the target leaf, interface, encapsulation VLAN, physical domain, VLAN pool, and deployment settings. A mismatch in any of these components can prevent the endpoint from receiving the intended EPG policy. Static bindings therefore provide precise physical endpoint attachment within ACI.<\/span><\/p>\n<h3><b>Question 384<\/b><\/h3>\n<p><b>Which ACI policy object determines which application protocols and ports are permitted by a contract?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">VRF<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Bridge domain<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Filter<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Application profile<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A filter defines the specific traffic characteristics that a contract can permit, including protocols and source or destination ports. Filters are associated with contract subjects, which determine how the traffic rules are applied. A VRF provides routing separation, a bridge domain provides forwarding characteristics, and an application profile organizes related EPGs. When an application cannot communicate despite having a contract relationship, administrators should inspect the filter entries carefully. The configured protocol and port values must match the application&#8217;s actual traffic. Filter-based contracts provide a reusable way to implement application-level security without configuring individual endpoint ACLs.<\/span><\/p>\n<h3><b>Question 385<\/b><\/h3>\n<p><b>Which ACI access-policy component provides VLAN resources to a physical or virtual domain?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Contract<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">VLAN pool<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">External EPG<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Interface selector<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A VLAN pool provides VLAN identifiers that can be allocated to physical or virtual connectivity domains. The domain references the VLAN pool so that the appropriate encapsulation resources are available when EPGs are deployed. Contracts control communication policy, External EPGs represent external destinations, and interface selectors identify physical interfaces. If an EPG cannot deploy because an encapsulation is unavailable, administrators should inspect the associated domain and VLAN pool configuration. They should verify that the required VLAN exists in the pool and that the pool is correctly associated with the domain. Proper VLAN resource planning helps avoid access-policy deployment problems.<\/span><\/p>\n<h3><b>Question 386<\/b><\/h3>\n<p><b>Which ACI feature allows selected EPGs within the same VRF to communicate without requiring individual contracts for every relationship?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Endpoint retention<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Preferred group<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">ARP flooding<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Resolution immediacy<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Preferred groups provide a mechanism for selected EPGs within the same VRF to communicate according to preferred-group policy without requiring individual contracts for every relationship. This can simplify policy design when several EPGs have similar communication requirements. Endpoint retention manages learned endpoint information, ARP flooding controls ARP behavior, and resolution immediacy affects policy dependency resolution. Administrators should carefully define preferred-group membership because it changes the normal contract-based communication model. When troubleshooting preferred-group connectivity, they should verify the EPG membership, VRF association, preferred-group configuration, and whether the intended EPGs are actually included in the policy.<\/span><\/p>\n<h3><b>Question 387<\/b><\/h3>\n<p><b>Which ACI component represents an external network destination for policy purposes?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">External EPG<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Application profile<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Physical domain<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">VLAN pool<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An External EPG represents external network destinations connected through ACI external connectivity. External subnets can be associated with an External EPG, allowing contracts to control communication between internal EPGs and external networks. Application profiles organize internal EPGs, physical domains provide physical endpoint connectivity, and VLAN pools provide VLAN encapsulation resources. External EPGs are commonly used with L3Out configurations to establish policy boundaries for north-south traffic. If internal workloads cannot communicate with an external network, administrators should check the External EPG subnet definitions, L3Out configuration, routing state, route-control policies, and contracts.<\/span><\/p>\n<h3><b>Question 388<\/b><\/h3>\n<p><b>Which ACI routing technology can be configured on an L3Out to exchange routes using a link-state protocol?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">BGP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">OSPF<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">CDP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">LLDP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">OSPF is a link-state routing protocol that can be configured through an ACI L3Out to exchange routes with external OSPF-speaking devices. It establishes neighbor relationships and exchanges link-state information to construct routing knowledge. BGP is a path-vector routing protocol, while CDP and LLDP provide neighbor-discovery information rather than route exchange. When troubleshooting OSPF through an L3Out, administrators should verify the area configuration, interface addressing, neighbor state, routing policy, and route-control settings. A healthy OSPF adjacency does not necessarily mean the desired application routes are available, so route advertisement and import policies should also be checked.<\/span><\/p>\n<h3><b>Question 389<\/b><\/h3>\n<p><b>Which ACI component provides direct physical connectivity for servers attached to the fabric?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">APIC<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Spine switch<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Leaf switch<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">External router<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Leaf switches provide direct physical connectivity for servers, appliances, and other endpoints attached to the ACI fabric. They are responsible for endpoint attachment and policy enforcement before traffic is forwarded through the spine layer. APIC provides management and policy orchestration, spine switches provide fabric transit, and external routers connect the ACI environment to outside networks. When an endpoint cannot connect, administrators should check the leaf interface, interface policy, EPG attachment, VLAN encapsulation, endpoint learning, and bridge-domain configuration. Because endpoints normally connect directly to leaf switches, the leaf is a critical starting point for physical and policy troubleshooting.<\/span><\/p>\n<h3><b>Question 390<\/b><\/h3>\n<p><b>Which ACI setting controls whether a bridge domain performs Layer 3 forwarding?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Unknown unicast<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Endpoint retention<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Unicast routing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">ARP flooding<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The unicast routing setting determines whether Layer 3 routing is enabled for a bridge domain. When enabled, the bridge domain can provide Layer 3 gateway functionality through its configured subnet. Unknown-unicast behavior controls Layer 2 frames with unknown destinations, endpoint retention controls learned endpoint information, and ARP flooding controls ARP request handling. If endpoints can communicate locally but cannot reach other subnets, administrators should verify unicast routing, the bridge-domain subnet, VRF association, and relevant contracts. Correct configuration ensures that the bridge domain can participate in Layer 3 forwarding and provide the expected gateway functionality to connected endpoints.<\/span><\/p>\n<h3><b>Question 391<\/b><\/h3>\n<p><b>Which ACI feature controls how ARP requests are flooded within a bridge domain?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Deployment immediacy<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">ARP flooding<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Route control<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Preferred group<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">ARP flooding controls the handling of ARP requests within a bridge domain when traditional flooding behavior is required. Certain applications and network designs depend on ARP requests reaching other endpoints in the broadcast domain. Deployment immediacy controls when policy is programmed, route control influences external routing, and preferred groups simplify selected EPG communication. When an endpoint cannot resolve another endpoint&#8217;s IP address, administrators should review ARP flooding along with the bridge-domain subnet, endpoint learning, and gateway configuration. Correct ARP behavior can be important for applications that rely on conventional Layer 2 address resolution within their network segment.<\/span><\/p>\n<h3><b>Question 392<\/b><\/h3>\n<p><b>Which ACI access-policy object combines multiple interface policies such as CDP, LLDP, and link aggregation settings?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Interface policy group<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Interface selector<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Switch profile<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Physical domain<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An interface policy group combines multiple individual interface policies into a reusable configuration for a physical interface. Depending on the design, it can include policies for CDP, LLDP, speed, link aggregation, storm control, and other interface behaviors. The interface selector identifies which interfaces receive the policy group, the switch profile associates configuration with leaf switches, and the physical domain provides endpoint connectivity resources. When troubleshooting a physical port, administrators should inspect the policy group and verify that its constituent policies match the intended interface behavior. Proper grouping simplifies access-policy management and promotes consistent configuration across multiple interfaces.<\/span><\/p>\n<h3><b>Question 393<\/b><\/h3>\n<p><b>Which ACI object is used to organize multiple EPGs belonging to the same application?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">VRF<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Application profile<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Contract<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">VLAN pool<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An application profile organizes multiple EPGs that belong to the same application or logical service. For example, an application profile can contain separate EPGs for web, application, and database tiers. A VRF provides the routing context, contracts define communication policy, and VLAN pools provide encapsulation resources. Application profiles help administrators manage policy in an application-centric manner rather than organizing configurations solely around physical network locations. When troubleshooting an application, administrators can begin with the application profile and inspect its EPGs, contracts, bridge domains, domains, and endpoint attachments to determine where a policy or connectivity problem exists.<\/span><\/p>\n<h3><b>Question 394<\/b><\/h3>\n<p><b>Which ACI object provides the logical interface configuration for an L3Out connection?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">External EPG<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Logical interface profile<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Application profile<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Contract subject<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A logical interface profile defines the logical interface configuration associated with an ACI L3Out. It works with the logical node profile to represent the external routed connection and can contain interface-specific addressing and routing configuration. External EPGs represent external destinations, application profiles organize internal EPGs, and contract subjects define how filters are applied. When troubleshooting an external interface, administrators should verify the logical interface profile, logical node profile, physical interface path, IP configuration, routing protocol, and VRF. Correct logical interface configuration is necessary for establishing the intended Layer 3 relationship between the ACI fabric and an external network.<\/span><\/p>\n<h3><b>Question 395<\/b><\/h3>\n<p><b>Which ACI feature provides rapid detection of failures between supported network peers?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">BFD<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">CDP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">LLDP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">VXLAN<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">BFD provides rapid detection of forwarding-path failures between supported peers. It can operate with routing protocols to reduce the time required to detect a failed path compared with relying only on normal routing-protocol timers. CDP and LLDP provide neighbor discovery, while VXLAN provides overlay encapsulation. When troubleshooting a BFD session, administrators should verify the underlying interface connectivity, peer configuration, BFD parameters, and session state. A BFD failure can indicate an underlying path problem rather than an isolated BFD configuration issue. Proper BFD deployment can improve convergence behavior when supported routing or forwarding connections fail.<\/span><\/p>\n<h3><b>Question 396<\/b><\/h3>\n<p><b>Which ACI management method uses a dedicated management network separate from the production fabric?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">In-band management<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Out-of-band management<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Preferred-group management<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Contract-based management<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Out-of-band management uses a dedicated management network that is separate from the production data-plane fabric. This provides an alternative management path that can remain available when certain production-fabric forwarding or policy problems occur. In-band management uses the ACI fabric itself to transport management traffic, while preferred groups and contracts are policy constructs rather than management methods. When designing operational access, administrators should consider the availability requirements and failure scenarios of each method. Out-of-band management can be particularly useful during severe fabric troubleshooting because management access does not depend on normal production traffic forwarding.<\/span><\/p>\n<h3><b>Question 397<\/b><\/h3>\n<p><b>Which ACI object controls the communication relationship between consumer and provider EPGs?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Contract<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">VLAN pool<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Physical domain<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Interface selector<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A contract controls the communication relationship between a consumer EPG and a provider EPG. It defines which services or traffic types the consumer is allowed to access through subjects and filters. VLAN pools provide encapsulation resources, physical domains associate EPGs with physical connectivity, and interface selectors identify physical interfaces. When a consumer cannot reach a provider application, administrators should verify that the provider is actually providing the intended contract and that the consumer is consuming it. They should also inspect the contract subject, filter entries, VRF association, and endpoint connectivity. Contracts provide reusable, policy-based security between application groups.<\/span><\/p>\n<h3><b>Question 398<\/b><\/h3>\n<p><b>Which ACI overlay technology is used to carry tenant traffic across the leaf-and-spine fabric?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">OSPF<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">BGP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">VXLAN<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">CDP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">VXLAN is the overlay encapsulation technology used by ACI to transport tenant traffic across the leaf-and-spine fabric. It allows logical networks and endpoint policies to be carried across the physical infrastructure while maintaining segmentation. OSPF and BGP are routing protocols, while CDP is used for neighbor discovery. VXLAN works together with ACI endpoint learning and policy enforcement to determine how traffic is forwarded. When troubleshooting overlay communication, administrators should verify endpoint learning, EPG deployment, bridge-domain settings, leaf-to-spine connectivity, and policy resolution. VXLAN provides the transport mechanism, while ACI policy determines how endpoints communicate.<\/span><\/p>\n<h3><b>Question 399<\/b><\/h3>\n<p><b>Which ACI component represents a collection of external IP prefixes that can be used in policy relationships?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">External EPG<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Interface policy group<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">VMM domain<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Application profile<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An External EPG can contain external subnet definitions representing networks outside the ACI fabric. These external destinations can participate in contract-based policy relationships with internal EPGs. Interface policy groups define physical interface behavior, VMM domains integrate virtualization platforms, and application profiles organize internal EPGs. External EPGs are commonly used with L3Out configurations to provide a policy boundary for north-south traffic. When external connectivity fails, administrators should verify the External EPG subnet definitions, L3Out association, VRF, routing protocol state, route-control policies, and contracts. Correct configuration ensures that external prefixes are represented properly within the ACI policy model.<\/span><\/p>\n<h3><b>Question 400<\/b><\/h3>\n<p><b>Which ACI feature determines when an EPG&#8217;s required policy resources are resolved before deployment?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Endpoint retention<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Resolution immediacy<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Unknown unicast behavior<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Intra-EPG isolation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Resolution immediacy controls how quickly ACI resolves the policy dependencies required for an EPG before the policy can be deployed. It is part of the EPG deployment behavior and can affect how quickly the fabric determines the resources and relationships needed for policy installation. Endpoint retention controls learned endpoint information, unknown-unicast behavior controls Layer 2 handling, and intra-EPG isolation controls communication among endpoints in the same EPG. When an EPG policy does not appear on the expected leaf, administrators should review resolution immediacy together with deployment immediacy, domain association, VLAN pools, path bindings, and interface policies.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Cisco CCNP Data Center 300-620 Exam Dumps and Practice Test Dumps. &nbsp; Question 381 Which ACI component provides the centralized interface for configuring tenants, EPGs, contracts, and fabric policies? Spine switch APIC Leaf switch External router Correct Answer: 2 Explanation APIC provides the centralized management and policy interface for Cisco ACI. Administrators use [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/21254"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=21254"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/21254\/revisions"}],"predecessor-version":[{"id":21255,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/21254\/revisions\/21255"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=21254"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=21254"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=21254"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}